User Registration & Membership <= 5.2.2 - Unauthenticated Privilege Escalation
Strategic Overview
<= 5.2.2CVE-2026-11961Vulnerability Overview
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.2.2. This makes it possible for unauthenticated attackers to register as administrators when a site administrator has explicitly created a membership role with admin capabilities. This is not something we consider a vulnerability, and was rejected by our team.
Technical Analysis
REMEDIATION: Update to version 5.2.3, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C